Description
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated local file inclusion flaw exists in Version 2.4.11 and earlier of the Restaurant Menu by MotoPress plugin. The vulnerability allows an attacker to include arbitrary files on the server that are normally inaccessible to web users, potentially exposing sensitive configuration files or other private data. No explicit mention of remote code execution is provided, but the availability of arbitrary file discovery can be a stepping stone to other attacks if the server environment is misconfigured.

Affected Systems

The issue affects installations of the WordPress plugin "Restaurant Menu by MotoPress" by jetmonsters, specifically all versions up to and including 2.4.11. Users running any of these iterations are susceptible to the exploitation described.

Risk and Exploitability

The flaw carries a CVSS score of 8.1, indicating high impact. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is likely through a crafted request to the plugin’s URL, and because no authentication is required, the vulnerability is exploitable by any user who can reach the affected WordPress installation.

Generated by OpenCVE AI on August 18, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WordPress Restaurant Menu by MotoPress plugin to any version later than 2.4.11 where the LFI flaw is addressed.
  • If an immediate update is not possible, restrict web‑server access to the plugin folder (adjust file permissions or use .htaccess rules) to prevent traversal of sensitive directories.
  • If the plugin is no longer required, remove or deactivate it to eliminate the vulnerable code from the site.

Generated by OpenCVE AI on August 18, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetmonsters
Jetmonsters restaurant Menu By Motopress
Wordpress
Wordpress wordpress
Vendors & Products Jetmonsters
Jetmonsters restaurant Menu By Motopress
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
Title WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jetmonsters Restaurant Menu By Motopress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:40:51.422Z

Reserved: 2026-08-12T14:10:14.732Z

Link: CVE-2026-73400

cve-icon Vulnrichment

Updated: 2026-08-18T14:40:45.453Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:07.530

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:45:04Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')